Company

Access control that mirrors how organizations actually work

Canopy is hierarchical identity and access management for B2B SaaS: full authentication, enterprise SSO and directory sync, and roles that inherit down your customers' org tree. Infrastructure you rely on, not code you maintain.

Built for the developers who'd otherwise build org-hierarchy and permission systems themselves again and again
Why we exist

The wheel everyone reinvents

Every B2B SaaS app eventually has to answer one question. The industry's standard answer breaks the moment a customer has structure.

01
The problem

Flat RBAC breaks on real organizations

Sooner or later, every B2B app must answer: “Can this user do this action, in this part of the organization?” The standard answer is flat role-based access control: a user gets a role, the role has permissions. It works until a customer has regions, offices, departments, franchises, or teams. Then a flat list of roles can't express who can do what, where, and teams end up building a custom hierarchy-and-permissions system from scratch.

02
The gap

Flat RBAC has no concept of structure

Flat role-based access control is the industry standard, and it stops at a flat list. A role applies everywhere or nowhere, so it can't say a regional manager has access across their region but not others. That missing layer, permissions that inherit down an org tree, is what teams end up building from scratch, then securing and maintaining forever.

03
What we built

Hierarchical IAM, as infrastructure

Canopy provides the full authentication lifecycle, enterprise SSO (SAML + OIDC) and SCIM directory sync, and the differentiator: hierarchical RBAC. Assign a role at any node in the tree and its permissions inherit downward automatically. It starts as flat RBAC and grows into hierarchy with no migration: the same roles, now scoped to structure.

04
What we believe

Authorization shouldn't be rebuilt by everyone

Access control that reflects how organizations are actually structured should be something you depend on, not something each company writes, secures, and maintains on its own.

Authorization is infrastructure, not boilerplate.
The platform

One platform for the whole identity stack

Authentication, enterprise SSO and directory sync, and the hierarchical authorization teams usually build by hand, together in one place.

Capability Included
Authentication & session management
Enterprise SSO: SAML & OIDC
SCIM directory sync
Role-based access control
Hierarchical RBAC with inheritance Defines Canopy

Hierarchical permission inheritance (a role assigned at any node in your org tree cascades to everything beneath it) is the capability that defines Canopy.

What we stand for

Principles, grounded in how it's built

Not slogans. These map directly to decisions in the product.

Authorization is infrastructure

Access control belongs in a system you depend on, not boilerplate every company writes, secures, and maintains itself.

Security by default

Modern password hashing, MFA, SSO and SCIM, full audit logging, and environment-isolated secrets: on by default, not bolted on.

Built for real organizations

Hierarchy and inheritance, not flat lists, because regions, departments, and teams are how companies are actually shaped.

Developer-first, operator-friendly

An API developers integrate in hours, plus an Admin Workspace non-engineers can actually use to manage access.

Isolation as a discipline

Strict Account → Application → Environment boundaries, so a change in development can never reach into production.

Flat to hierarchical, no migration

Start with simple roles and grow into a full org tree when you need it. The same roles carry forward. Your code doesn't change.

Why you can depend on it

A complete platform, isolated by design

Canopy isn't a thin RBAC layer. It's the full identity stack, with tenant isolation built into the architecture, not added later.

Security by default

Real authentication rigor, applied everywhere, not a checklist for later.

Modern password hashing and MFA built into the auth lifecycle
Enterprise SSO & SCIM: SAML, OIDC, and directory sync
Full audit logging of every security-sensitive action
Environment-isolated secrets: never shared across contexts

Isolation by architecture

Every tenant is sealed by a strict three-tier boundary.

Account
the customer tenant
Isolated
Application
a product within the account
Scoped
Environment
dev / staging / production
Sealed

A change in one environment can never touch another.

Get in touch

Talk to Canopy

Whether you're evaluating, buying, or just curious, here's how to reach us.

Sales & enterprise

SSO, SCIM, custom limits, security review, or a guided evaluation.

Contact sales

General & partnerships

Press, partnerships, or anything that doesn't fit a box. Say hello.

Get in touch

Developers

Read the docs, browse the API, and start building in minutes.

Open the docs

Stop rebuilding authorization.

Build your product. Let Canopy handle hierarchical access control, starting today.